CVE-2026-71325 Details
Description
Traefik is an open-source edge router that makes publishing services a fun and easy experience. Prior to 2.11.54, 3.6.25, and 3.7.10, cross-namespace @kubernetescrd references are not rejected for TraefikService backend references resolved by the service resolver. A tenant confined by RBAC to a single namespace can therefore bind its own router to a TraefikService owned by another namespace and expose or reroute that namespace's backend, defeating the namespace isolation allowCrossNamespace=false is meant to enforce. This issue is fixed in version 2.11.54, 3.6.25, 3.7.10.
A vulnerability exists in Traefik's Kubernetes CRD provider, allowing cross-namespace service references to be improperly handled. When 'allowCrossNamespace' is disabled, references should be restricted to the same namespace. However, prior to the patched versions, TraefikService backend references could still be resolved across namespaces. This flaw enables a tenant restricted to a single namespace to bind a router to a TraefikService in another namespace, potentially exposing or rerouting that namespace's backend services. This behavior undermines the intended namespace isolation.
Users should upgrade to Traefik versions 2.11.54, 3.6.25, or 3.7.10, where this vulnerability has been fixed.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Aug 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-653 | Improper Isolation or Compartmentalization | [email protected] |
| CWE-863 | Incorrect Authorization | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| traefik traefik | < 2.11.54 >= 3.0.0, < 3.6.25 >= 3.7.0, <= 3.7.10 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 16, 2026 | Initial Analysis | [email protected] |
| Aug 7, 2026 | CVE Modified | CISA-ADP |
| Aug 6, 2026 | New CVE Received | [email protected] |